TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Vercel employee used customer information to pursue a personal trademark matter

191 点作者 StanAngeloff超过 1 年前

11 条评论

NicoJuicy超过 1 年前
This was only one part of the story?<p>1. Vercel shipping Indie hackers projects ( their customers) as &quot;app templates&quot; as a host, for marketing purpose<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;nico_jeannen&#x2F;status&#x2F;1712749652133683632?t=oAcu_ZnC9Zqc_GBjibeb4g&amp;s=19" rel="nofollow noreferrer">https:&#x2F;&#x2F;twitter.com&#x2F;nico_jeannen&#x2F;status&#x2F;1712749652133683632?...</a><p>2. The mentioned infringement of a Vercel employee, mentioned here ( he seems to be fired)<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;nico_jeannen&#x2F;status&#x2F;1713139186474406206?t=4O_HTGKSkZY6pok46xcRdQ&amp;s=19" rel="nofollow noreferrer">https:&#x2F;&#x2F;twitter.com&#x2F;nico_jeannen&#x2F;status&#x2F;1713139186474406206?...</a><p>3. Very broad ToS -&gt; Vercel may delete your app for no reason at all<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;bk_7312&#x2F;status&#x2F;1713197808264839479?t=h1TeEZlsjv3KbmAL0DVKSw&amp;s=19" rel="nofollow noreferrer">https:&#x2F;&#x2F;twitter.com&#x2F;bk_7312&#x2F;status&#x2F;1713197808264839479?t=h1T...</a>
koopuluri超过 1 年前
This is really concerning.<p>This combined with their marketing strategy of copying popular indie products and turning them into NextJS templates creates paranoia in the minds of builders who trust Vercel with their codebases, analytics, and often even their data (via Vercel&#x27;s storage products).<p>It seems that an enterprising Vercel employee has a goldmine of data to help inform their next &quot;side project&quot;.
评论 #37887385 未加载
hubraumhugo超过 1 年前
&gt; Employees can easily access the user&#x27;s data and impersonate any account<p>At every decent sized company I&#x27;ve worked for, topics like production data privileges, data classification (public, sensitive, confidential, etc.), data masking, and data anonymization for testing have been top priorities. And these policies are sometimes a true pain in the ass for developers, but they exist for a good reason.<p>I guess you shouldn&#x27;t miss the timing to go from &quot;move fast and break things&quot; to &quot;ok we&#x27;re now a serious business&quot;.
评论 #37887387 未加载
评论 #37887531 未加载
hipadev23超过 1 年前
Isn&#x27;t this like the 5th or 6th time Vercel accessed private information from customers to launch a competitive service and&#x2F;or shutdown the customer?<p>Is there some tech incubator clause buried in their TOS and this is all okay?
评论 #37887399 未加载
jlund-molfese超过 1 年前
More context: <a href="https:&#x2F;&#x2F;twitter.com&#x2F;nico_jeannen&#x2F;status&#x2F;1713139186474406206" rel="nofollow noreferrer">https:&#x2F;&#x2F;twitter.com&#x2F;nico_jeannen&#x2F;status&#x2F;1713139186474406206</a>
lloydatkinson超过 1 年前
Vercel is rapidly turning into a scourge in the open source world. Their strong coupling to React is also worrying, they are already trying to influence future React features for their NextJS framework.
评论 #37893663 未加载
mdhb超过 1 年前
Add it to the long list of evidence that Vercel is a shady af company who shouldn’t be trusted.
评论 #37887520 未加载
throwaway290超过 1 年前
Tangentially, who else misses the time when React was just a side project by FB? Increasingly it seems to be led by Vercel who makes profit from React-based solutions.
评论 #37887282 未加载
评论 #37887266 未加载
评论 #37887576 未加载
评论 #37887211 未加载
pc_edwin超过 1 年前
&gt; The employee did not have access to any source code, secrets, or the ability to change settings or deployments.<p>We are talking about an employee who has access to the customers personal information as part of their job doing something unethical.<p>I would be extremely surprised if Vercel didn&#x27;t have industry systems and practices in place for security.<p>This is an edge case which can only be avoided by building Google-esque systems and practices. I don&#x27;t think you guys really understand what your asking for here.<p>This will cripple them in so many ways, it makes so much more sense delay it as long as possible. Not because they can save a bit of money, but because they UX will fall of a cliff, feature velocity will ground to a halt and the product will drift further away from stuff we really want.
osbulbul超过 1 年前
Well, I already don&#x27;t like vercel and just sign up to test couple of things. But after I read this, I am going to delete my test account.
jatins超过 1 年前
In my experience at early stages of a company data ACLs are often the last priority for companies. People are rewarded for shipping things that can get a mention in company&#x27;s next board deck, and &quot;added ACLs to our Postgres&quot; never got a mention in a board deck.<p>I am sure a half motivated employee at your favorite cab service could see which addresses you frequently commuted to in first few years of that service&#x27;s existence
评论 #37889919 未加载